apparmor bind blacklist blacklist-nolog caps.drop caps.keep cpu dbus-system.broadcast dbus-system.call dbus-system.own dbus-system.see dbus-system.talk dbus-user.broadcast dbus-user.call dbus-user.own dbus-user.see dbus-user.talk defaultgw dns env hostname hosts-file ignore include ip ip6 iprange join-or-start keep-fd mac mkdir mkfile mtu name net netfilter netfilter6 netmask netns nice noblacklist noexec nowhitelist overlay-named private private-bin private-cwd private-etc private-home private-lib private-opt private-srv protocol read-only read-write restrict-namespaces rlimit-as rlimit-cpu rlimit-fsize rlimit-nofile rlimit-nproc rlimit-sigpending rmenv seccomp seccomp-error-action seccomp.32 seccomp.32.drop seccomp.32.keep seccomp.drop seccomp.keep timeout tmpfs veth-name whitelist whitelist-ro xephyr-screen